EASVD: A Modified Method to Enhance the Authentication for SPICE Virtual Desktop
Chao Liu, Xinling Shen, Nan Li · 2019
Virtual Desktop (VD) provides a convenient way for users to operate their virtual machines on different types of terminals. SPICE is an excellent protocol for the VD display. However, there are still several threats when using the original SPICE in the high-level scenarios. The threats are mainly due to the fact that the original SPICE ignores the confidentiality of the VD. The threats contain the data interaction like copying, falsifying, and deleting between VDs & different physical terminals. Furthermore, the original SPICE authentication is a one-factor method based on the IP address and password of the user. We bind each VD to a specific authorized terminal to reduce the threat posed by the data interaction between VDs and physical terminals in the high-level security scenarios proposed in our paper. At the same time, we propose a two-factor authentication method which includes physical terminals authentication and user-password authentication. We also reinforce the security of the VD by putting forward a modified way to storage the password. Our approach to intensify the VDs authentication has been implemented in terminals based on SPICE and Libvirt. Our method can effectively prevent the unauthorized users from illegal logging into the VD on the illegal physical terminals, even when the correct password is intercepted by unauthorized users. We demonstrate the effectiveness of our method by experimental results.